What a CVV dump is
A CVV dump is a record of stolen payment card data that includes the card verification value, the short security code printed on a card. Criminals bundle these records into files and trade them on hidden forums. The file is not a product you can buy, test, or use. Every part of that trade is a crime, and any site offering to sell one is either a fraud or a police operation.
If you arrived here because the term showed up in a message you received, or because a charge on your statement does not look right, the sections below explain what happened and what to do next.
Why the CVV matters
Card networks treat the CVV as evidence that whoever is paying has the physical card in hand. Merchants are allowed to ask for it to approve a purchase, but they are not allowed to store it after the transaction completes. That single rule is why stolen card numbers without a matching code often fail at checkout, and why fraudsters keep pushing buyers for the code. A dump that contains a card number, expiry date, and CVV is worth more to a criminal than a number alone, which is exactly why it is treated as a serious offence.
How card data ends up in a dump
- Skimming devices attached to fuel pumps and cash machines
- Fake online stores that copy a real brand and harvest checkout details
- Breaches at retailers that failed to secure their payment systems
- Phishing emails that imitate a bank, a courier, or a gift retailer
- Malware on a home computer that captures keystrokes at checkout
Greeting card and gift shops are targeted because orders are small, frequent, and often shipped to a third party, which makes a stolen card harder to trace.
What the law says
In the United States, buying, selling, or using stolen card credentials falls under wire fraud, access device fraud, and identity theft statutes, with penalties that include prison time and restitution. Similar laws exist across the European Union, the United Kingdom, Canada, and Australia. There is no legitimate market for dumps, no consumer protection, and no refund when a seller disappears with your payment.
How to protect your card when buying cards and gifts online
- Type the retailer address yourself instead of tapping a link in a message.
- Check that the checkout page loads over a secure connection before entering card details.
- Use a virtual card number or a payment service that masks your real number when a shop is unfamiliar.
- Turn on transaction alerts in your banking app so unusual charges reach you the same day.
- Keep your CVV out of emails, chat messages, and order notes. No real retailer asks for it that way.
- Review statements for your gift purchases once a month, not once a year.
If your card is already compromised
- Call the number on the back of your card and ask the issuer to freeze the account.
- Request a replacement card with a new number and a new CVV.
- Dispute every charge you do not recognise in writing.
- Change the password on the shopping account where the card was saved.
- Report the incident to your national fraud reporting body and keep the reference number.
Quick answers
Is a CVV dump the same as a fullz?
No. A fullz usually bundles a name, address, date of birth, and sometimes a Social Security number. A dump focuses on the card itself. Both are stolen records and both are illegal to hold.
Can I check whether my card is in a dump?
You cannot search criminal marketplaces directly, and you should not try. Your card issuer can confirm whether a number has been flagged, and a credit freeze or fraud alert will block most attempts to open new accounts in your name.
Does a gift card order need my CVV?
Yes, at the payment step of a normal checkout. It never needs to be sent by email, text, or social message, and no courier or delivery notice will ask for it.